7 ms·
So is nginx with http2 enabled vulnerable too? Caddy? I should I not worry about this, because a small (by Cloudflare scale) botnet may DDoS a single server com
by anshargal 3y ago
So is nginx with http2 enabled vulnerable too? Caddy? I should I not worry about this, because a small (by Cloudflare scale) botnet may DDoS a single server completely anyway?
- mholt 3y agoGo is patching it soon: https://github.com/caddyserver/caddy/issues/5877#issuecomment-1755810980 https://github.com/caddyserver/caddy/issues/5877#issuecommen... (Caddy just uses Go's HTTP/2 implementation.)
- bwesterb 3y agoGo patches are out. (1.21.3, 1.20.10)
- otbutz 3y agonginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ https://www.nginx.com/blog/http-2-rapid-reset-attack-impacti... caddy: https://github.com/caddyserver/caddy/issues/5877 https://github.com/caddyserver/caddy/issues/5877
- thresh 3y agonginx: https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html https://mailman.nginx.org/pipermail/nginx-devel/2023-October...